⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Thinkst Applied Research |
| Support Tier | Partner |
| Support Link | https://help.canary.tools/ |
| Categories | Security - Threat Protection |
| Version | 3.0.0 |
| Author | Thinkst Applied Research - support@canary.tools |
| First Published | 2026-08-18 |
| Last Updated | 2026-08-18 |
| Solution Folder | ThinkstCanary |
The Thinkst Canary solution for Microsoft Sentinel ingests Canary and Canarytoken incidents through the Codeless Connector Framework and provides normalized parsers, detections and response automation.
This solution provides 1 data connector(s):
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
ThinkstCanaryIncidents_CL |
Thinkst Canary | Analytics |
This solution includes 1 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Canary alerts to incidents | High | LateralMovement, Exfiltration | ThinkstCanaryIncidents_CL |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 18-08-2026 | Initial CCF connector and analytic rule for ingesting and detecting Thinkst Canary and Canarytoken incidents. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊